Which technology tracks changes to secure data integrity?

A security administrator needs a method to secure data in an environment that includes some form of checks so track any changes. Which of the following should the administrator set up to achieve this goal?

  1. SPF
  2. GPO
  3. NAC
  4. FIM Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests knowledge of data integrity controls, specifically FIM's ability to monitor and alert on file modifications — the common trap is confusing FIM with GPO, which configures settings but does not track file-level changes.

File Integrity Monitoring (FIM) is the correct solution for tracking changes to critical files and ensuring data integrity in an enterprise environment. Community consensus overwhelmingly confirms FIM as the answer, noting its ability to detect unauthorized modifications through baseline comparisons and hash digests.

Some candidates may select GPO (Group Policy Object), mistakenly believing it can enforce and track data changes, but GPO is a configuration management tool that does not provide file-level integrity monitoring or change detection.

Community Discussion (5 comments)

Etc_Shadow28000 👍 10 Selected: D
D. FIM (File Integrity Monitoring) File Integrity Monitoring (FIM) is a security technology that monitors and detects changes in files. FIM solutions can track modifications, access, or deletions of files and notify administrators of any changes, thus ensuring data integrity and security. Therefore, the correct answer is: D. FIM
Examplary 👍 10
Note to the admins: There is a typo in this one. "checks SO track any changes" should be "checks TO track any changes"
Syl0 👍 7
SPF - Sender policy framework - identify mail servers that are allowed to send emails to domain GPO - Group Policy Object - let admin control and implement a group of settings NAC - Network Access Control - Restricts unauthorised users and devices from gaining access to the network FIM - File Integrity Monitoring - security process that monitors and analyses integrity of asset
whatsupdeepak 👍 4
FIM - stands for File Integrity Monitoring, which is a method to secure data by detecting any changes
Abcd123321 👍 2 Selected: D
File Integrity Monitoring (FIM) ■ Validates the integrity of operating system and application software files by comparing their current state with a known, good baseline ■ Identifies changes to ● Binary files ● System and Application Files ● Configuration and Parameter Files ■ Monitors critical system files for changes using agents and hash digests, triggering alerts when unauthorized changes occur

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

FIM (File Integrity Monitoring) is specifically designed to validate the integrity of operating system and application files by comparing their current state against a known good baseline. It uses agents and hash digests to monitor critical system, binary, and configuration files, triggering alerts when unauthorized changes occur. This directly satisfies the requirement to "secure data" and "track any changes" as stated in the question.

Why the Other Options Are Wrong

SPF (Sender Policy Framework) is an email authentication protocol that identifies authorized mail servers — it has nothing to do with file or data integrity. GPO (Group Policy Object) is used to configure and enforce settings across Windows environments but does not monitor or track file modifications. NAC (Network Access Control) restricts unauthorized devices from accessing the network but provides no file-level change tracking capabilities.

Community Comment Notes

Comment [1] correctly defines FIM as monitoring and detecting file changes including modifications, access, and deletions. Comment [3] provides excellent concise definitions of all four acronyms, making it a valuable study reference. Comment [5] offers the most detailed technical explanation, noting FIM's use of hash digests and baseline comparisons, which aligns with CompTIA's official curriculum on integrity monitoring tools.

Official Reference

Exam Strategy

When you see keywords like 'track changes,' 'integrity,' or 'monitor modifications' in a security question, immediately think of FIM. Eliminate distractors by matching each acronym to its primary function: SPF for email, GPO for configuration, NAC for network access.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide